EDIH, EEN, Interreg: the platform for European programmes.Find out more

Data Act Maturity · European Data Regulation

Your Data Act obligations translated into a score, documented gaps and a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Data Act Maturity · European Data Regulation

Mapping of product and service dataN1 → N5
User right of accessN1 → N5
Transfer to a designated third partyN1 → N5
Design and pre contractual informationN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Mapping of product and service data6484
User right of access5379
Transfer to a designated third party6182
Design and pre contractual information3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • ANITI
  • CNRS
  • LIRMM
  • CNES
  • Docaposte
  • KPMG

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Regulation (EU) 2023/2854 of 13 December 2023 (Data Act), applicable since 12 September 2025 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism, one level, the next level up, and the action linking the two, is what turns a finding into a trajectory.

Is the data generated by your connected products identified and made available to the user who requests it?

  1. N1

    Data generated by products is not inventoried. No user access request has been handled.

  2. N2

    A partial inventory exists for a few product ranges. Access requests are handled case by case, through manual extraction, with no stated timeframe.

  3. N3

    The inventory covers the main product ranges. A documented provision process exists, with a stated format and timeframe, and is generally applied.

  4. N4

    Provision relies on a documented interface, requests and transfers to third parties are logged, timeframes are measured and gaps are addressed.

  5. N5

    Access is built into the design of new products, provision indicators are reviewed periodically and interface changes follow a documented cycle.

Action to move from L2 to L3

Complete the inventory of data generated across the main product ranges, publish a provision process with a stated format and response timeframe, and add tracking of received requests to the quarterly product review.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon DATA ACT.

What this framework covers

The Data Act, Regulation (EU) 2023/2854 adopted on 13 December 2023 and applicable since 12 September 2025, covers data generated by connected devices and their related services. It gives users a right to access the data they generate and the right to have it transferred to a third party of their choosing. It sets rules for data sharing contract terms, protects small businesses against unfair clauses, organises the provision of data to public bodies in cases of exceptional need and requires data processing service providers to remove obstacles to switching provider.

In practice, the difficulty is organisational before it is legal. The text assumes you know what data a product generates, in what format, to what quality, and who holds it today. Practical questions arise quickly: does your catalogue cover equipment telemetry data, or only data from management systems? Do your existing contracts provide for access and transfer to a third party, or must they be renegotiated one by one? Do your interfaces allow provision within a stated timeframe, or do they rely on manual extraction?

Two confusions come up often. The first equates the Data Act with GDPR. The two apply together, but GDPR protects individuals and their personal data, whereas the Data Act organises the economic circulation of data, including industrial and non-personal data. The second treats it as a legal matter alone. In fact its effects centre on product design, interface architecture, the documentation given to the user and the portability of cloud services.

A compliance audit concludes with a gap or an absence of a gap, on a given date. The maturity assessment answers a different question: what level of control does each practice sit at, and what specific action moves it up a level. For a regulation whose effects progressively reach new products placed on the market, this level-based view lets you sequence the effort instead of tackling everything at once.

The framework is ready to use and remains adaptable. AI adjusts themes, questions and level wording to your sector, industrial machinery, medical devices, mobility or data processing services, or builds a variant from your own documents, standard contracts and product sheets.

Reference standard: Regulation (EU) 2023/2854 of 13 December 2023 (Data Act), applicable since 12 September 2025

The themes assessed

  • Mapping of product and service data

    Inventory of connected products and related services, nature of data generated, raw data and metadata, formats, quality, location, internal owner.

  • User right of access

    Arrangements for provision, timeframes, free of charge access, secure access, request handling, traceability of provisions made.

  • Transfer to a designated third party

    Process for transfer at the user’s request, recipient verification, fair and non discriminatory conditions, controls over prohibited uses.

  • Design and pre contractual information

    Data accessibility planned from the design stage, user information provided before purchase, technical documentation, available access interfaces.

  • Data sharing contract terms

    Standard contracts, remuneration for sharing, control of unfair terms towards small businesses, alignment with confidentiality and trade secrets.

  • Protection of trade secrets

    Identification of sensitive data, proportionate technical and organisational measures, conditions for refusal or suspension, reasoned and traceable decisions.

  • Switching data processing service providers

    Exit clauses, notice periods, migration assistance, portability of data and exportable digital assets, removal of transfer fees, functional equivalence.

  • Interoperability and interfaces

    Use of interoperability standards and specifications, documented interfaces, version management, automated rather than manual extraction capability.

  • Provision to public sector bodies

    Procedure for responding to requests based on exceptional need, points of contact, timeframes, applicable limits, logging of exchanges.

  • Governance and oversight

    Allocation of roles between legal, product, data and IT, monitoring indicators, periodic review, training for the teams involved.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Can the Data Act be certified?

No. It is a directly applicable European regulation, with no dedicated certification body. The assessment measures the maturity of your practices, documents gaps and prepares you for checks or requests from customers and partners. It issues no certificate.

How does this differ from a compliance audit?

An audit records a gap or an absence of a gap on a given date. The assessment places each practice on a progressive scale and shows the action that moves it up a level. The two complement each other: the assessment sequences the effort, the audit validates it.

Does the Data Act replace GDPR?

No, the two apply together. GDPR protects individuals and their personal data. The Data Act organises access to and sharing of data generated by connected products, personal or not, and the portability of data processing services.

Who should answer the questions?

The assessment draws on several functions: data, legal, product and IT. The collaborative mode lets you assign each theme to the right contributor, then consolidate the answers into a single score per theme.

How long does the assessment take?

The short version can be completed in a single working session. The full version, in collaborative mode with several contributors, takes one to two weeks, most of the time spent gathering input from product and legal teams.

Can the framework be adapted to our sector?

Yes. You can change the questions, levels and themes, or start from your own documents: AI then builds a variant tailored to your product ranges and standard contracts. The framework is yours.

How can this assessment link to our other data and AI assessments?

Cross-cutting roadmaps consolidate several audits, for example data governance, the AI Act and the Data Act. AI groups converging actions together to avoid tackling the same workstream twice.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.

Take your first measurementon DATA ACT.