Svenska Dokumentmallar
Data Act Template Package 2026 – Agreements & Compliance Word/PDF/Excel
Data Act Template Package 2026 – Agreements & Compliance Word/PDF/Excel
Downloading the template is available immediately after purchase. Our document templates are always delivered in customizable formats.
If you are unsure which template is appropriate or how you should complete it, please see the relevant information under the 'Legal Information' tab in our main menu.
Our templates are designed in accordance with current legislation and practice in each area to ensure that the documents you create are legally correct.
Couldn't load pickup availability
Data Act Template Package 2026 – agreements, data sharing and cloud switching
A complete compliance package for companies affected by the EU Data Act (Regulation (EU) 2023/2854). The package is designed for Swedish companies working with connected products, related digital services, data sharing, third-party access, or data processing services such as cloud, SaaS, PaaS, and IaaS.
The Data Act began to apply on September 12, 2025. As of September 12, 2026, Article 3(1)’s specific design requirements also apply to connected products and related services placed on the market after this date. The package is updated and legally reviewed as of October 2, 2026.
Included – 9 files
- Data Holder – User, agreement template in Word (DOCX)
- Data Holder – User, PDF
- Data Holder – Data Recipient, agreement template in Word (DOCX)
- Data Holder – Data Recipient, PDF
- Cloud Switching & Exit Addendum, Word (DOCX)
- Cloud Switching & Exit Addendum, PDF
- Data Act Compliance Guide & Checklist 2026, Word (DOCX)
- Data Act Compliance Guide & Checklist 2026, PDF
- Data Act Compliance 2026 – Excel tool with registers, monitoring, and control
1. Agreement between Data Holder and User
The first agreement template is intended for the relationship between the entity holding readily available data from a connected product or related service and the user who has rights under the Data Act. The template regulates, among other things:
- product data and related service data
- data catalogs, metadata, and technical formats
- direct and indirect access
- APIs, export functions, and other interfaces
- free access for the user where required by the Data Act
- the data holder’s use of non-personal data
- the user’s right to request sharing with third parties
- personal data and the relationship to the GDPR
- trade secrets and protective measures
- security limitations
- prohibited competitive use of data
- incidents, amendments, and termination
2. Agreement between Data Holder and Data Recipient
The second agreement template is used when a user requests that a data holder makes data available to an external third party. It is particularly relevant for companies building services on top of IoT, automotive, machine, energy, industrial, or other product data.
The template includes provisions regarding the user’s instruction, data quality, technical delivery, permitted use, further sharing, compensation, trade secrets, personal data, security, and non-discriminatory terms.
Reasonable compensation and the SME rule
When Article 9 of the Data Act is applicable, compensation for making data available between businesses must be non-discriminatory and reasonable. The package contains a specific compensation annex where costs for, among other things, formats, electronic transfer, and storage can be documented.
If the data recipient is an SME or a qualified non-profit research organization, the compensation may be specifically limited under Article 9(4). The template therefore contains specific fields for SME status and cost documentation.
3. Cloud Switching & Exit Addendum
The cloud section is designed for data processing service agreements where the Data Act's rules on provider switching are applicable. It can be used as an addendum to, for example, SaaS, PaaS, or IaaS agreements and regulates, among other things:
- switching to another provider
- porting to local ICT infrastructure
- exportable data and digital assets
- notice period for initiating a switch
- transition period
- reasonable technical assistance
- operational continuity
- security during transfer
- APIs and export formats
- data retrieval period
- final deletion
- switching fees and the transition to 2027
- information on international governmental access to non-personal data
Important cloud dates
The Data Act requires, among other things, that relevant cloud agreements clearly describe the switching process. The maximum notice period to initiate the switching process may generally not exceed two months, and the mandatory maximum transition period is generally 30 calendar days. Furthermore, the customer must have at least a 30-calendar-day data retrieval period after the transition period where the rules are applicable.
From January 12, 2027, switching charges under Article 29 must be fully abolished. Until then, only reduced switching charges may be levied within the limits specified by the Data Act.
4. Compliance Guide 2026
The guide helps the business determine where the Data Act affects the organization and how implementation can be structured. It includes, among other things:
- scope test for roles and operations
- important dates
- product and service mapping
- data mapping
- Article 3 design requirements
- user access and third-party sharing
- trade secrets
- B2B compensation
- unfair unilaterally imposed data terms
- cloud switching
- Swedish supplementary legislation and current status
- implementation checklist
- legal sources and EU Commission guidance
5. Excel tool for practical implementation
The Excel file is built as a working tool, not just an empty table. It contains separate sheets for:
- Scope – role assessment and applicability
- Products – connected products and related services
- Data Catalog – product data, service data, formats, metadata, and access
- Requests – register of user and third-party requests
- Recipients – data recipients, compensation, and protective measures
- Cloud Switching – control of notice period, transition, export, and deletion
- Agreement Review – risk control for unfair terms under Article 13
- Actions – compliance plan with person responsible, priority, and deadline
- Sources – primary EU sources and Swedish legislative status
The dashboard automatically calculates, among other things, the number of mapped products, open access requests, active data recipients, cloud services needing action, and open compliance actions.
For connected products after September 12, 2026
Article 3(1) implies that relevant connected products and related services placed on the market after September 12, 2026, must be designed so that product data and related service data, including relevant metadata, are by default easily and securely accessible, free of charge, comprehensive, structured, commonly used, and machine-readable, and – where relevant and technically feasible – directly accessible to the user.
This means that the Data Act is not just a legal contractual matter. For many businesses, it is also a matter of product architecture, API design, metadata, user portals, and internal data flows.
Trade secrets
The Data Act does not mean that trade secrets must automatically be disclosed without protection, but trade secrets are not a general exception to data access either. The package therefore contains clauses for proportionate technical and organizational protective measures, documentation, and specific handling of situations where the data holder needs to withhold, suspend, or, in exceptional cases, refuse access according to the Data Act’s conditions.
Unfair data terms between businesses
Chapter IV contains specific rules on unilaterally imposed B2B terms regarding data access, data use, liability, and remedies. Certain terms may be directly unfair or presumed to be unfair. The compliance tool therefore contains a specific agreement review tab.
The EU Commission’s model terms
The EU Commission has published non-binding model terms for data access and data use as well as standard clauses for cloud computing contracts. The templates in this package are independently designed Swedish documents that build on the Data Act’s binding requirements and use the Commission’s guidance as support. They are not a verbatim copy of the Commission’s models.
Swedish status 2026
The Data Act is an EU regulation and applies directly. Sweden is simultaneously working on supplementary rules regarding, among other things, the competent authority, sanctions, and dispute resolution. SOU 2025:118 has proposed supplementary Swedish legislation and designated the Swedish Post and Telecom Authority (PTS) as the competent authority. As of the product's review date, the Swedish legislative chain is still marked as ongoing, which is taken into account in the guide.
Legal basis
- Regulation (EU) 2023/2854 of the European Parliament and of the Council (Data Act)
- GDPR – Regulation (EU) 2016/679, where personal data is processed
- applicable Swedish contract and trade secret law
- EU Commission Data Act FAQ and implementation material
- EU Commission non-binding MCT/SCC material
Suitable for, among others
- IoT and hardware companies
- machine and industrial companies
- automotive and mobility services
- energy and smart-grid solutions
- SaaS, PaaS, and IaaS providers
- system integrators
- data and analysis services
- companies receiving product data at the customer’s request
- legal, compliance, and IT functions
Important to know
The Data Act is technically and contractually dependent on the business’s actual products, data flows, roles, and system architecture. The templates must therefore always be adapted. The package does not replace individual legal advice in complex, cross-border, or litigious situations.
Format: Word (DOCX) + PDF + Excel (XLSX)
Language: Swedish
Jurisdiction: Sweden / EU
Number of files: 9
Version: 1.0 – 2026-10-02
Share



