The EU Data Act: Cloud Switching and Data Portability
The EU Data Act is rewriting cloud contracts and killing switching fees by January 2027. Here is what it changes for your data, your providers, and your lock-in.
Most of the EU digital rulebook lands on people who build software. The Data Act is different: it lands on the contracts you already signed. Regulation (EU) 2023/2854 entered into force in January 2024 and its core provisions started applying on 12 September 2025, and it does something the earlier laws did not. It hands you, the customer, a set of rights over data and over the providers that hold it. The two that matter most to a business running on cloud infrastructure and SaaS: you can move your data out, and you can switch provider without the exit tax that used to make leaving unthinkable.
That second part has a hard date attached. From 12 January 2027, switching fees for cloud services in the EU are abolished outright, egress charges included. If your architecture quietly assumes a customer can never afford to leave, that assumption expires in a little over a year. Here is what the Data Act actually changes, and the parts worth acting on now rather than in December 2026.
What the Data Act is, and what it is not
The Data Act is about access to data and fairness in who controls it, not about privacy. GDPR governs personal data; the Data Act governs the far larger pile of non-personal, machine-generated and operational data that businesses sit on. The two overlap at the edges but answer different questions. GDPR asks "may you hold this person's data?" The Data Act asks "can the customer get their data back, and can they leave?"
It has four moving parts. Rights for users of connected products to access the data those products generate. Fairness rules that void abusive data-sharing contract terms. A narrow public-sector access right for exceptional need. And the one most businesses will feel first: mandatory, low-friction switching between cloud and data-processing services. It applies to providers offering services into the EU regardless of where they are headquartered, the same extraterritorial reach as GDPR.
The quick test
If you buy cloud infrastructure or SaaS, or you sell a connected product that generates data for your customers, the Data Act reaches you. If you only process EU personal data, that is still GDPR's job, not this.
The end of cloud lock-in
The switching rules are the headline. Providers of cloud and data-processing services now have to remove the commercial, technical, and contractual obstacles that keep customers stuck. In practice that means three things.
- A capped clock. Once you initiate a switch, the provider has to complete it within 30 calendar days. If it is genuinely not technically feasible in that window, the period can extend, but the burden is on the provider to justify it, not on you to beg.
- Real portability. Contracts have to guarantee you can take your data and "digital assets" out in a structured, commonly used, machine-readable format, through open, standardised interfaces. "Export as a proprietary blob nobody else can read" does not satisfy this.
- Fees on the way down, then gone. Since September 2025 switching charges are restricted to the direct costs the provider actually incurs. From 12 January 2027 they disappear completely, including the egress fees that have long made moving terabytes out of a hyperscaler a five-figure decision.
The strategic point is not that everyone will suddenly switch. It is that the threat of switching becomes credible, which changes the negotiation. A renewal conversation with a provider who knows you can leave for the price of the migration work, and nothing more, is a different conversation.
Your right to the data your products generate
If you make connected products, sensors, machines, vehicles, smart devices, the Data Act gives your users a right to the data those products produce, and a right to share it with a third party of their choosing, including a competitor of yours. A fleet operator can pull the telemetry off its vans and hand it to an independent maintenance firm. A factory can route machine data to whichever analytics vendor it likes, not just the OEM's.
For manufacturers this is a design requirement, not a legal footnote. The data has to be accessible "by default and, where relevant, continuously and in real time". Retrofitting that onto a product that was built to keep its data inside a closed portal is expensive. Building it in from the start is cheap. If you have hardware with a software backend on the roadmap, the access design belongs in the first architecture review.
Watch the trade-secret line
The Act protects legitimate trade secrets, so you are not forced to expose proprietary algorithms. But "it is a trade secret" is not a blanket excuse to withhold operational data the user is entitled to. The two get argued case by case, so document which is which before a customer asks.
What changes in your contracts
Two contract-level shifts are worth flagging to whoever owns your agreements.
First, unfair data-sharing terms are unenforceable. The Act lists terms that are presumptively abusive when imposed unilaterally, particularly on smaller counterparties, and strikes them out. A clause that lets one side change the data rules at will, or that dumps all liability on the weaker party, may simply not hold.
Second, new cloud contracts already have to comply. Agreements signed from 12 September 2025 onward must carry the switching and portability terms. So the fine print you signed last month may already give you exit rights your last renewal did not. It is worth actually reading it before you assume you are trapped.
What to do in the next few months
You do not need a compliance programme to get ahead of this. Start with what you can see.
- Map your lock-in. For each critical cloud and SaaS dependency, write down how you would get the data out and what format it comes in. The exercise usually surfaces one or two providers where the honest answer is "we have no idea", and those are your real risk.
- Read your newest contracts. Anything signed after September 2025 should already carry switching and portability language. Know what rights you have before a renewal, not during one.
- Prefer open formats and standard interfaces in anything you build or buy from here, so portability is a property of the system rather than a project you fund later.
- If you ship connected products, put data access in the architecture now. Real-time, structured access to product data is far cheaper designed in than bolted on under a customer complaint.
This is the same lesson as keeping your data in the EU with sovereign cloud and knowing when moving off the cloud pays off: the value is in keeping your options open. It also pairs with the EU Cyber Resilience Act guide as the other half of the 2026-2027 compliance calendar for anyone who sells software or connected devices in Europe.
If you want a candid read on where you are locked in, how hard it would actually be to leave, and how to build the next system so portability is free rather than a hostage situation, talk to us. We will map the parts that apply to you and the parts you can safely ignore.
Written by
Rafael Costa
Software Engineer & Technical Writer
Rafael is a software engineer at Lusivision who writes about web development, cloud architecture and applied AI. He has spent over a decade shipping production software for companies across Europe and enjoys turning hard technical topics into clear, practical guides.
View all articles