If you already understand what the Data Act is and why connected-vehicle data matters, the question that keeps a dealer principal awake is narrower and more practical: what do we actually have to do, and by when. This EU Data Act compliance checklist is written for teams who are past the explainer stage and need a concrete sequence of steps, contract clauses to review, and roles to assign before the rules start to bite.

The Data Act does not arrive as a single switch you flip on a deadline. It reshapes who can access data generated by connected products and related services, what the holder of that data must provide, and on what terms it can be shared with third parties. For a dealership group, that touches the vehicles you sell and service, the systems your suppliers run, and the contracts you have signed without reading the data clauses closely. The work below turns that into a defensible position rather than a vague worry.

Start with the obligation, not the panic

Before building a checklist, be precise about which Data Act roles apply to you, because the obligations differ.

  • You are often a user of connected products and related services: the vehicles, telematics, and software your dealership operates generate data you have a right to reach.
  • You may be a data holder in some relationships, for example where your DMS or your own systems hold data that a customer or a downstream service provider is entitled to request.
  • You will frequently sit between an OEM or vendor and an end customer, which means access requests can flow through you in both directions.

You do not need a legal opinion on every edge case to begin. You need to know which systems hold what, and which contracts govern access. For the conceptual grounding on how these roles map onto the trade, the companion piece on the Data Act and the automotive industry is worth reading alongside this checklist, and the question of who owns vehicle data in Europe sets up why the access rights matter at all.

Note
Exact application and enforcement timelines depend on the regulation's staged provisions and on national implementation. Treat the steps below as a readiness sequence and confirm specific dates with your legal adviser rather than relying on a single hard deadline.

The compliance checklist

Work through these in order. Each step produces an artefact you can show an auditor, a customer, or a board.

1. Map your data flows

You cannot answer a request for data you have not located. Produce a simple inventory that records, for each significant system:

  • What data it holds (vehicle records, service history, telematics, valuations, customer records).
  • Where the data physically and legally sits, including which cloud region and which jurisdiction.
  • Who the holder is, who can already access it, and through what interface.
  • Whether you can export it, in what format, and how long that takes.

This inventory is the spine of everything that follows. A dealership that has consolidated its records can produce it in days; one running on disconnected systems will discover how much the work of unifying data has been deferred. The pattern of fragmented records is common enough that it has its own failure mode, covered in dealership data silos.

2. Classify what you must be able to share

Not all data is in scope, and not all in-scope data is equally sensitive. Sort your inventory into categories so that an access request does not trigger a scramble.

Data categoryTypical examplesAccess posture
User-generated product dataTelematics, usage, service eventsLikely subject to user access and sharing rights
Derived and enriched dataValuations, scores, internal analyticsReview case by case; document how it was produced
Personal dataCustomer identity, contact, finance recordsGDPR continues to apply on top of Data Act rules
Trade secrets and pricing logicMargin models, sourcing rulesProtectable, but must be identified and justified

The point of the table is to avoid two opposite errors: over-disclosing data you were entitled to protect, and under-disclosing data a user has a clear right to receive. Field-level clarity about where a number came from makes this far easier, which is why data lineage for dealers is more than a technical nicety here.

3. Review your contracts for lock-in

This is the step with the highest commercial payoff. Pull every material supplier agreement, especially your DMS and any telematics or software vendor, and check for:

  • Data portability: can you extract your full dataset, in a usable open format, without an exit fee that effectively traps you.
  • Switching terms: notice periods, transition assistance, and whether the vendor must help you migrate rather than simply hand over a final dump.
  • Unfair contractual terms: the Data Act constrains terms unilaterally imposed on smaller parties, so clauses that looked immovable may no longer be enforceable.
  • Third-party access: how a request from your customer to share data with a competitor or independent service is actually handled in practice.

If a contract cannot answer these questions cleanly, that is your renegotiation list. The law has shifted the leverage toward you; the value is only realised if you act on it. The mechanics of leaving without breaking your operation are covered in how to switch your DMS without downtime.

4. Stand up an access-request process

Even if you expect few requests at first, you need a defined route so the first one does not land on nobody's desk.

  1. Name an owner accountable for receiving requests, from customers and from authorised third parties.
  2. Define a triage step: confirm identity, confirm the requester's right, and classify the data using your step-2 categories.
  3. Set an internal turnaround target and a template response, including how you handle partial refusals on trade-secret grounds.
  4. Log every request and its outcome, so you can demonstrate a consistent, good-faith process.

5. Fix your formats and your sovereignty posture

Two structural choices determine how painful every future request will be: whether your data lives in open, portable formats, and whether it is held under EU jurisdiction. Proprietary formats and opaque cloud arrangements turn each request into a project. Open formats that the customer genuinely owns turn it into an export. This is where compliance and competitive advantage converge, an argument set out in full in EU data sovereignty as a competitive advantage.

Tip
When you negotiate or renew any data contract from here on, treat "open format, customer-owned, exportable on demand" as a non-negotiable line item. It is cheaper to insist on it at signing than to litigate it at exit.

6. Train the people who touch the data

A checklist that lives only with the compliance lead fails at the counter. The service advisor who is asked by a customer to send their telematics history to an independent garage needs to know that this is now a routine, lawful request with a defined process, not something to refuse or escalate informally. A short briefing on who owns what, and where requests go, prevents both unlawful refusals and careless over-sharing.

What good looks like by the time the rules bite

A dealer who has worked the checklist can state, in one page, what data they hold, where it sits, which contracts govern it, and how a request is answered. They have renegotiated at least the worst lock-in clause. They have an owner and a log. That is a defensible position. The dealer who has done none of this is exposed not because the law is punitive on day one, but because the first real access request reveals that the underlying records were never in order.

The deeper reading is that the Data Act rewards the operators who had already treated their data as an asset to govern rather than a by-product to ignore. Compliance and good operations point in the same direction.

Where VehIQ fits

VehIQ is being built as the data layer that makes this checklist easier to satisfy rather than harder. The design principles map directly onto Data Act readiness: canonical European vehicle data with field-level lineage, so you can answer where a value came from; open formats the customer owns, so portability is an export rather than a negotiation; and an EU-sovereign posture by default. VehIQ is pre-seed and these are design commitments, not deployed results. But the direction is deliberate: a dealership that runs on data it genuinely owns, in open formats, under EU jurisdiction, is not scrambling when an access request arrives. It is already compliant by construction, and free to switch, share, and negotiate from a position of strength.