What should a Data Act classification record contain for this FAQ?
A useful classification record should be narrow: product or service name, data field, generation source, whether the field is product data or related service data, whether it is readily available, the metadata needed to interpret it, the enrichment level, and the reason for any exclusion. For personal data, trade secrets, or security-sensitive data, classification should be paired with the relevant safeguards rather than used as a reason to ignore the Data Act category.
The record should also support Article 3 pre-contractual transparency about type, format, estimated volume, generation frequency, storage or retention, access and retrieval, the data holder, third-party sharing, and the trade-secret holder where relevant. The Article 3(1) duty to design for direct access where relevant and technically feasible applies to connected products and related services placed on the market after 12 September 2026.
- Track each field's Data Act category and whether it is raw, pre-processed, inferred, derived, content, or unavailable.
- Record necessary metadata, format, access route, storage, retention, and data holder identity.
- Separate classification from safeguards for GDPR, trade secrets, security, and contractual use limits.
Article 3 lists pre-contractual information for connected products and related services, including data type, format, volume, frequency, retention, access, and data holder details.
Explains the practical factors for deciding which data is in scope of Data Act access rights.