| name | arckit-eu-data-act |
| title | User Input |
| description | [COMMUNITY] Assess EU Data Act (Regulation 2023/2854) compliance for connected products, data holders, and data processing service providers |
| author | tractorjuice |
| author_url | https://github.com/tractorjuice/arc-kit/tree/main/arckit-codex/skills/arckit-eu-data-act |
| license | MIT |
| version | 0.1.1 |
| execution_mode | open |
| jurisdiction | eu |
| practice | data-protection |
| language | en |
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified DPO / RSSI / legal counsel before reliance. Citations to ANSSI / CNIL / EU regulations may lag the current text — verify against the source.
You are helping an enterprise architect generate a EU Data Act Compliance Assessment (Regulation EU 2023/2854) for an organisation that manufactures connected products, holds data generated by those products, or provides data processing services. Most Data Act obligations apply from 12 September 2025.
User Input
$ARGUMENTS
Instructions
Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.
Step 0: Read existing artifacts from the project context
MANDATORY (warn if missing):
- REQ (Requirements) — Extract: product type (connected product vs software service), data generation and collection requirements (DR-xxx), data sharing requirements (INT-xxx), cloud service type (IaaS/PaaS/SaaS)
- If missing: warn that Data Act scoping requires understanding of product type and data flows
RECOMMENDED (read if available, note if missing):
- DATA (Data Model) — Extract: data types generated, data flows, personal data vs non-personal data, industrial/IoT data categories
- RISK (Risk Register) — Extract: data sharing risks, trade secret risks, cloud lock-in risks
- SECD (Secure by Design) — Extract: data access controls, API security for data sharing
OPTIONAL (read if available, skip silently):
- RGPD (GDPR Assessment) — Extract: personal data handling in data sharing — Data Act applies alongside GDPR when data contains personal data
- SECNUM (SecNumCloud) — Extract: cloud provider sovereignty — complements Data Act Article 27 (international transfer restrictions)
Step 0b: Read external documents and policies
- Read any external documents in
external/ — extract existing data sharing agreements, product technical specifications, cloud provider contracts, trade secret registers