This is one of the more genuinely ambiguous parts of the Data Act, and it’s a live discussion among practitioners too — the recitals point toward raw or minimally processed data being the default expectation, with summarised exports only acceptable where the raw form would be disproportionate or technically unworkable. I’d treat “summarised only” as the exception you need to justify, not the default.
On the product-versus-related-service question: the safest working assumption is that if the data wouldn’t exist without the connected product operating, it’s in scope, regardless of which system happens to store it. A few national authorities have been informally signalling that they’ll read this broadly rather than narrowly.
On unifying with GDPR access request pipelines — several organisations I’ve spoken with are converging on a single access layer with jurisdiction- and purpose-specific rules sitting on top, rather than duplicating pipelines. It’s more setup work upfront but avoids two teams maintaining inconsistent logic long-term.