The EU Data Act Gave You the Right to Leave Your Cloud Provider — Check Your Contract

The EU handed every cloud customer a statutory right to leave their provider without penalty. Most contracts, including ones signed well after the right became enforceable, still don’t reflect it — and the deadline to stop paying to leave arrives 12 January 2027.

I’ve written elsewhere about measuring vendor lock-in before you sign. The Data Act’s cloud-switching provisions, in force since 12 September 2025 under Chapter VI, Articles 23 to 31, change that calculus specifically for cloud, edge, and SaaS services offered to EU customers — regardless of where the provider is established. This isn’t a best-practice recommendation. It’s a binding legal right, and most organisations haven’t checked whether their current contracts actually deliver it.

What the right actually guarantees

Article 23 requires providers to actively remove — not merely avoid adding — barriers that inhibit a customer from terminating a contract, signing with a replacement provider, and porting exportable data and digital assets to that replacement or to on-premise infrastructure. Article 25 sets mandatory minimum contract terms: a maximum two-month customer notice period to begin switching, a transition period capped at 30 days in the ordinary case, extendable in exceptional circumstances to as long as seven months, and a minimum 30-day window after the transition for the customer to retrieve remaining data before full erasure.

Free · 4 minutes

Do you know what could take the business down — and have you priced it?

Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.

The economic piece follows a defined glide path rather than a single cutover. Providers may charge cost-covering switching fees now, but Article 29 eliminates switching charges entirely from 12 January 2027 — meaning the current phase, as of today, is the last window in which any switching cost can legitimately be passed to the customer, and that window is closing on a fixed date, not a negotiable one.

Why most contracts still don’t reflect this

The scope is broader than most legal reviews initially assume — IaaS, PaaS, and SaaS all qualify, from infrastructure hosting to CRM platforms to industry-specific SaaS tools, provided the service meets the Act’s functional definition of a data processing service. Narrow exemptions exist for genuinely bespoke, custom-built solutions and for non-production test environments, but general-availability SaaS products don’t get a pass simply because they’re software rather than raw infrastructure.

Most existing contracts, including many signed after September 2025, were drafted before switching became a serious commercial consideration and simply don’t contain Article 25’s mandatory terms — no defined notice period matching the statutory maximum, no committed transition timeline, no exhaustive specification of what data and digital assets are actually portable. A contract silent on these points isn’t automatically non-compliant in a way that protects the provider; the statutory right exists regardless of what the contract says, but a contract that doesn’t reflect it leaves both sides litigating what should have been settled in writing.

The practical audit

For any organisation relying on EU-facing cloud or SaaS contracts, the exercise is concrete: check whether the current agreement actually states the notice period, transition timeline, and portable-data specification the Act requires, and check the fee structure against the January 2027 zero-charge deadline rather than assuming current pricing will simply persist. For providers, the same audit runs in reverse — existing contract templates almost certainly need updating, and the European Commission’s non-binding model contractual terms, expected to mature through 2026, are worth tracking as they firm up rather than guessing at compliant language independently.

This right also reframes part of the vendor-lock-in conversation I’ve written about elsewhere: for EU-facing cloud services specifically, “how expensive would it be to leave” now has a statutory floor underneath it that didn’t exist before September 2025, and any lock-in assessment done today should check the current contract against that floor rather than assuming the market’s old assumptions about switching cost still hold.

What the audit actually found, in practice

A mid-sized financial services firm reviewing its core SaaS contracts ahead of a routine renewal discovered that its primary case-management platform’s terms specified a six-month notice period for termination — three times the Data Act’s statutory maximum — and no committed transition timeline at all, just a vague reference to “reasonable cooperation.” Nobody had renegotiated the contract since it was signed in 2023, well before the Data Act’s provisions applied, and nobody had checked it against the new statutory floor since. Flagging the gap and requesting compliant terms at renewal cost the firm nothing beyond the conversation — the vendor, once pressed, updated the contract without resistance, because the statutory obligation gave the firm leverage the original contract never granted it. The whole exercise took an afternoon of legal review against a checklist; the alternative was discovering the six-month notice period only when the firm actually needed to leave.

This right only helps if lock-in was actually being measured before it became relevant — see measuring vendor lock-in before you sign.

Auditing existing cloud and SaaS contracts against Data Act switching requirements — and checking pricing models against the January 2027 zero-charge deadline — is a concrete, bounded piece of work a technology control assessment can complete quickly, for either side of the contract.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming