The Data Act Gives You a Right to Switch Cloud Providers. Whether You Can Use It Depends on Your Technology.
Chapter VI of the Data Act makes switching providers the provider's obligation. Obstacles have to go, the switch runs on a fixed chain of deadlines and from 12 January 2027 it may not cost anything. Legacy contracts are not protected. What that means for your next contract renewal and what your technology needs to be able to do so that the right becomes a feasible move.
Key Takeaways
- Chapter VI of the Data Act has applied since 12 September 2025 to legacy contracts too, because Article 50 only contains transitional rules for Chapters III and IV.
- The well-known 30 calendar days are only the transitional period from Article 25. A notice period of up to two months comes first and where switching is technically unfeasible, up to seven months are possible.
- From 12 January 2027 switching charges are prohibited. Early termination penalties do not fall under that prohibition according to the definition in Article 2.
What changed on 12 September 2025
Anyone who wanted out of a cloud in recent years did the maths. Effort for the move against the remaining term, fees for pulling the data out against the discount for renewing. The result was almost always a renewal, because leaving cost more than staying. That was by design.
The Data Act, Regulation (EU) 2023/2854, entered into force on 11 January 2024 and has applied since 12 September 2025. Its Chapter VI, Articles 23 to 31, governs switching between data processing services. That means cloud services of every kind: rented computing power and storage, platforms and software (Alston & Bird). So not just the contract with the big cloud provider, but also the CRM, the data warehouse and the rented search function.
The maths turns into an entitlement. The provider has to remove obstacles, keep to deadlines and from a fixed date may not charge anything for the switch.
The problem lies elsewhere. The provider owes you an export. It does not owe you a system that runs at the new provider afterwards. A right to switch is worth little if your own technology does not allow the switch.
The point in one sentence
Since 12 September 2025 your cloud provider has to make switching possible, but whether your system runs afterwards depends entirely on your own technology.
Article 23 names five kinds of obstacle
The usual shorthand says the Data Act bans commercial, technical, contractual and organisational switching obstacles. That is one category short. Article 23 expressly names pre-commercial obstacles as well. What happens before the signature counts too.
That moves the moment at which dependency is created. Dependency is not created in the termination clause but at the start: in the developer kit the provider recommends as the fastest path and in the reference architecture that puts three provider-specific services in the critical path because that saves time on day one.
Article 23 sets out in points a to e what has to work in the end: terminating the contract after the notice period, concluding a new contract with a different provider, transferring the exportable data and digital assets, achieving functional equivalence at the new provider and unbundling individual services where technically feasible.
Functional equivalence means the system behaves at the new provider exactly as it did before. That is where most moves fail. Not because data is missing, but because behaviour is. An export contains rows. It does not contain the retry logic of a queue, the guarantees of a rented data store or the permission resolution of the provider’s own user management.
The 30 days are not the deadline you have in mind
Every summary mentions 30 calendar days. The number is correct, but describes only one link in a chain. Article 25(2)(a) sets a transitional period of at most 30 calendar days. That period only starts after the notice period in point (d). The notice period may be up to two months. Realistically you are looking at roughly three months, not one. Anyone counting the 30 days back from the end of the contract is off by eight weeks.
| Step | Basis | Duration |
|---|---|---|
| Notice period after the switching request | Art. 25(2)(d) | up to two months |
| Transitional period, standard case | Art. 25(2)(a) | at most 30 calendar days |
| Transitional period where technically unfeasible | Art. 25(4) | at most seven months |
| One-time extension by the customer | Art. 25(5) | as long as the customer considers appropriate |
| Time to retrieve the data afterwards | Art. 25(2)(g) | at least 30 calendar days |
Two rows get overlooked regularly. The first is technical unfeasibility. Under paragraph 4 the provider has to notify you within 14 working days of your switching request, give the reasons and state an alternative period of at most seven months. That is not an excuse, it is a procedure with a duty to give reasons and a ceiling. Anyone who does not know this accepts an informal refusal when a written justification and an end date are owed.
The second is the extension on your side. Under paragraph 5 you may extend the transitional period once by a period you consider appropriate.
Switching charges go to zero, termination penalties do not
Article 29(1) is unambiguous: from 12 January 2027 the provider may not charge anything for the switch. Until then paragraph 2 permits reduced charges. Under paragraph 3 those may not exceed the costs the provider incurs directly through the switch. A day rate for migration support with a margin built in is not covered.
The definition is what matters. Article 2(36) expressly excludes standard service fees and early termination penalties from the term switching charges. So the switching process becomes free. The remaining term stays owed.
Fees for pulling data out work similarly. Recital 99 makes clear that data egress charges for the parallel use of several providers, meaning without any intent to switch, may still be levied after three years from entry into force, capped at the costs incurred. The zero applies to switching, not to running several clouds side by side.
The market moved earlier than it had to. Google dropped egress fees for switching providers in January 2024, with AWS and Microsoft Azure following in March 2024 (CIO Dive). On 10 September 2025 Google Cloud announced Data Transfer Essentials: no-cost data transfer between clouds for customers in the EU and the UK, so for parallel operation too. That goes further than the regulation.
The legacy contract does not protect the provider
The most common misconception in renewal conversations: a contract signed before 12 September 2025 continues under the old rules. Article 50 contains transitional rules only for Chapters III and IV. There are none for Chapter VI. The switching obligations therefore apply without any grace period to contracts signed long before 12 September 2025 (Addleshaw Goddard).
That turns the negotiation around. The switching clause in your existing contract is no longer the governing rule, at best it describes what the provider volunteered. Until now you asked for switching rights and paid for them with a longer term. Now you only negotiate the implementation and test every clause against the statutory minimum.
| Point | What the law requires | What the legacy contract often says |
|---|---|---|
| Transitional period | at most 30 calendar days | assistance on a time and materials basis |
| Notice period for switching | at most two months | six months to end of term |
| Export format | structured, commonly used, machine-readable | provider’s own backup format |
| Switching charge | only costs directly incurred, zero from 2027 | day rates for migration support |
| Data retrieval after the switch | at least 30 calendar days | deletion at end of contract |
| Early termination | stays permissible | full remaining term falls due |
What Article 30 gives you and what it does not
Article 30 differentiates by service type. Providers of pure infrastructure, meaning computing power, storage and network, owe all reasonable measures in their power so that you achieve functional equivalence. That is a duty to make an effort, not a duty to succeed. All other providers, meaning platforms and software, owe open interfaces, equally for all customers and free of charge. As long as there are no common standards, the rule is: export of all exportable data in a structured, commonly used and machine-readable format. For implementing new standards the regulation allows at least twelve months after their publication.
Structured, commonly used and machine-readable is a clear legal standard and an inadequate technical target. A zip archive with 400 CSV files satisfies it. A running system it is not. The provider owes the export. Nobody owes you the restore. If you want to use the right, your side has to be built so that an export is enough.
Four decisions that make the right usable
The data model belongs to you, not to the service
If business objects, relationships and states exist only in the internal representation of a rented service, every export is a translation. Translations lose. If the same model sits in your own relational database and the service works on top of it, the export is a dump. In practice: no provider-specific column types in the schema of the critical path, no business logic in stored procedures of a provider-specific dialect and identifiers that stay stable outside the service.
Export formats get tested, not documented
An export path nobody has ever read back in is a claim. The only reliable check is a recurring restore attempt on neutral technology. Same idea as with backups: the write is not the test, the restore is.
The exit drill, once a month
- Trigger the export through the documented interface.
- Check that no provider-specific binary format is included.
- Load it into a neutral target environment, for example your own Postgres database and your own object storage.
- Run the business checks: the same permissions, the same totals, the same results for a handful of production-like queries.
The last step is the real one. It does not check row counts, it checks whether the business rules still hold after the import. Get that run green once and you have not merely demanded the functional equivalence of Article 23, you have measured it. It makes sense to hang the run off the same continuous monitoring as the rest of operations, so a quietly changed export format shows up immediately.
The configuration has to exist as text
The second big loss in a move is not the data, it is the settings: network rules, roles and permissions, queues, certificates, scaling parameters. When that state has grown over years inside a web console, it exists nowhere in readable form.
The Data Act changes none of that. It obliges the provider to make your data and digital assets portable, not to hand you a build sheet for your own environment. Infrastructure as code, meaning the entire configuration as versioned text files, is therefore the condition under which the 30 days are realistic. If you have to work out during the switch what the target environment should look like, you lose the deadline in planning, not in transfer.
Provider-specific services do not belong in the critical path
The fourth decision is the most uncomfortable, because it trades speed for freedom. A rented specialist service saves weeks on day one. In the critical path it costs months at switching time, because there is no counterpart at the new provider and the behaviour has to be rebuilt.
| Building block in the critical path | What happens when you switch | Preparatory work |
|---|---|---|
| Containers on standard images | rebuild in days | images in your own mirror |
| Relational database with an open dialect | dump and restore | no provider-specific extensions in the schema |
| Provider-specific data store | no counterpart at the new provider | intermediate layer or replacement before the renewal |
| Functions tied to provider events | event model not transferable | your own event bus as a layer |
| Permissions and network rules maintained in the console | reconstruction from memory | configuration as text as the single source |
| Rented search with its own query language | queries have to be rewritten | queries encapsulated in the application |
This is not a recommendation to run everything yourself. It is a recommendation to make the decision deliberately. Outside the critical path a provider-specific service is often the right choice. For the building blocks without which the business stops, it is a bet on the contract renewal. The SaaS graveyard is a reminder that providers also disappear without any involvement from you.
The exceptions that can take the right away from you
Two things belong in any honest assessment. The first is Article 31. Paragraph 1 covers services whose main features were mostly built for a single customer and that are not offered broadly in the provider’s catalogue. For those, functional equivalence, the ban on charges and parts of Article 30 do not apply. Paragraph 2 goes further: for test and preview versions provided for a limited time, the whole of Chapter VI does not apply. The provider has to inform you before the contract is signed which obligations do not apply. If that information is missing, take it as a signal.
The second is the Commission’s Digital Omnibus proposal of 19 November 2025. It would soften Chapter VI noticeably. Two new exceptions in Article 31 would exempt individually adapted services as well as small and medium-sized providers of non-infrastructure services from the switching obligations for contracts concluded before 12 September 2025, until those contracts end. Proportionate early termination penalties in fixed-term contracts would also be expressly permitted (Bird & Bird). As of early May 2026 this is a proposal under negotiation, not law in force.
That produces an uncomfortable imbalance. The right applies today, but could fall away again for a slice of legacy contracts. The technical groundwork keeps its value in both cases. A negotiating position resting solely on the statute does not.
Who enforces this
Supervision is organised nationally and Germany was late. The Bundestag passed the German implementing act for the Data Act on 26 March 2026 (Bundestag). It names the Bundesnetzagentur as the competent authority, including for the switching rules. Until the act enters into force there is no body in Germany where you can report a breach. That is more than seven months behind the date of application.
Article 40 sets the frame: Member States had to notify their penalty rules by 12 September 2025 and penalties have to be effective, proportionate and dissuasive. Fines up to the GDPR ceiling are only provided for infringements involving personal data, meaning Chapters II, III and V. For breaches of the switching rules each Member State sets the level itself. We are not aware of any concrete proceedings over switching obstacles as of the publication of this article.
The provider side has moved independently. CISPE, the association of European cloud infrastructure providers, published a Cloud Switching Framework together with Gaia-X in November 2024: clear information on procedures, costs and limits, notification channels for the switching request, export interfaces and tooling, an orderly termination procedure and contractual confirmation of the right to use several providers. AWS has published its own Data Act Addendum and Google Cloud a page on its implementation. These documents are the starting point of any renewal negotiation, not its outcome.
For context: in July 2025 Synergy Research put European providers’ share of the European cloud market at 15 percent, stable since 2022. AWS, Microsoft and Google together hold 70 percent. A right to switch only changes that distribution once switching is technically feasible in the time the law provides.
What you can check now
The Data Act moved the negotiating table, not your system landscape. Three steps bring the two together.
First: put the Article 25 chain of deadlines into every upcoming renewal and test the existing clauses against the table above. Anything falling short of the statutory minimum is an open question, not a negotiating win for the provider.
Second: make an honest list of the provider-specific services in the critical path. Not to replace them all, but to know which of them make the 30 days impossible. That list is the basis for any integration work that makes the right usable.
Third: run the exit drill once. Not as a concept, but as a green or red run. Everything else is a claim about your own mobility.
If you build connected devices, a second clock is running: from 12 September 2026 the access obligation in Article 3(1) applies to products newly placed on the market. If you want to know what this assessment looks like in a system landscape that has grown over years, talk to us.
This article is not legal advice. For the assessment of your specific contracts, obtain qualified counsel.
Sources
- Commission: Data Act (overview)
- Commission: Data Act FAQ, non-binding
- Data Act Art. 2 (definitions)
- Data Act Art. 23 (removing obstacles to switching)
- Data Act Art. 25 (contractual terms concerning switching)
- Data Act Art. 29 (gradual withdrawal of switching charges)
- Data Act Art. 30 (technical aspects of switching)
- Data Act Art. 31 (exemptions)
- Data Act Art. 40 (penalties)
- Data Act Art. 50 (entry into force and application)
- Data Act, recitals 91 to 100
- EUR-Lex: Regulation (EU) 2023/2854
- Bundestag: implementing act for the Data Act passed, 26 March 2026
- Google Cloud: Data Transfer Essentials, 10 September 2025
- Google Cloud: EU Data Act Compliance
- AWS: EU Data Act Addendum (PDF)
- Synergy Research: European cloud provider market share, 24 July 2025
- Alston & Bird: EU Data Act Switching Requirements
- Addleshaw Goddard: EU Data Act and SaaS contracts
- Bird & Bird: Digital Omnibus and the proposed changes to the Data Act
- CIO Dive: Azure eliminates egress fees (2024 chronology)
- CISPE: Cloud Switching Framework
Research for technical decisions
New reports, benchmarks and technical analyses on SaaS economics, AI engineering and owned infrastructure.
Original research Public sources No sales mail
By subscribing you receive new analyses and updates from FW Delta by email. You can withdraw your consent at any time. Further information is available in the privacy policy.